GRC Analyst
$65 - $85 per hourLHH Recruitment Solutions
Senior GRC Analyst - Security & Compliance LHH Recruitment Solutions is partnering with a high-growth, cloud-native SaaS organization to identify a Senior GRC Analyst to support and scale their security and compliance function. This role offers a unique opportunity to take ownership of a growing governance, risk, and compliance program within an innovative technology environment. The organization is building advanced, cloud-based products on Azure, with security and trust at the core of its platform. The Senior GRC Analyst will play a critical role in developing and operationalizing compliance frameworks, driving audit readiness, and establishing scalable, repeatable processes. This is an ideal opportunity for a GRC professional who is motivated to build and mature a program, work cross-functionally with engineering teams, and gain strong visibility with leadership. Preferred Office Alignment: San Francisco, CA
Employment Type: Contract (5+ months)
Pay Rate: $65-$85/hr (DOE) Key Responsibilities
Benefit offerings available for our associates include medical, dental, vision, life insurance, short-term disability, additional voluntary benefits, EAP program, commuter benefits and a 401K plan. Our benefit offerings provide employees the flexibility to choose the type of coverage that meets their individual needs. In addition, our associates may be eligible for paid leave including Paid Sick Leave or any other paid leave required by Federal, State, or local law, as well as Holiday pay where applicable.
Equal Opportunity Employer/Veterans/Disabled Military connected talent encouraged to apply To read our Candidate Privacy Information Statement, which explains how we will use your information, please navigate to The Company will consider qualified applicants with arrest and conviction records in accordance with federal, state, and local laws and/or security clearance requirements, including, as applicable:
Employment Type: Contract (5+ months)
Pay Rate: $65-$85/hr (DOE) Key Responsibilities
- Own and manage the Information Security Management System (ISMS), including policies, control frameworks, risk registers, vendor management, and Statement of Applicability.
- Lead ISO 27001:2022 and SOC 2 Type II initiatives end-to-end, including readiness assessments, evidence collection, control testing, remediation tracking, and audit coordination.
- Support the development and implementation of an ISO 42001 (AI management system) program alongside existing compliance frameworks.
- Serve as the primary point of contact for external auditors, managing audit timelines, evidence requests, and engagement logistics (e.g., Stage 1/Stage 2 audits, SOC 2 Type II).
- Administer and optimize the organization's GRC platform (e.g., Vanta, Drata, OneTrust), including control mapping, automated evidence collection, and monitoring control effectiveness.
- Conduct risk assessments, vendor risk reviews, and support security initiatives such as penetration testing, vulnerability disclosures, and bug bounty programs.
- Partner closely with engineering and technical teams to translate regulatory and compliance requirements into practical, scalable controls within an Azure-based environment.
- Support customer trust initiatives, including completion of security questionnaires, RFP responses, and maintenance of trust center documentation.
- 4+ years of experience in GRC, information security compliance, or IT audit, including participation in at least one full certification or audit cycle.
- Demonstrated hands-on experience with ISO 27001 and SOC 2 frameworks, including evidence management, auditor interaction, and remediation efforts.
- Familiarity with cloud security controls, preferably within Microsoft Azure environments.
- Experience working with GRC platforms such as Vanta, Drata, OneTrust, or similar tools.
- Strong skills in risk assessment, control design, and written communication.
- Exposure to AI governance frameworks (e.g., ISO 42001, NIST AI RMF) and AI security standards (e.g., OWASP LLM Top 10, MITRE ATLAS).
- Knowledge of data privacy regulations such as GDPR, particularly in relation to employee data.
- Relevant certifications such as ISO 27001 Lead Implementer or Lead Auditor, CISA, CRISC, CISSP, or CCSK.
- Experience in early-stage or high-growth SaaS environments.
- The California Fair Chance Act
- Los Angeles City Fair Chance Ordinance
- Los Angeles County Fair Chance Ordinance for Employers
- San Francisco Fair Chance Ordinance
Benefit offerings available for our associates include medical, dental, vision, life insurance, short-term disability, additional voluntary benefits, EAP program, commuter benefits and a 401K plan. Our benefit offerings provide employees the flexibility to choose the type of coverage that meets their individual needs. In addition, our associates may be eligible for paid leave including Paid Sick Leave or any other paid leave required by Federal, State, or local law, as well as Holiday pay where applicable.
Equal Opportunity Employer/Veterans/Disabled Military connected talent encouraged to apply To read our Candidate Privacy Information Statement, which explains how we will use your information, please navigate to The Company will consider qualified applicants with arrest and conviction records in accordance with federal, state, and local laws and/or security clearance requirements, including, as applicable:
- The California Fair Chance Act
- Los Angeles City Fair Chance Ordinance
- Los Angeles County Fair Chance Ordinance for Employers
- San Francisco Fair Chance Ordinance
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the GRC Analyst in San Francisco, CA vacancy
- ...Ivo is looking for a detail-oriented Governance, Risk & Compliance (GRC) Analyst in San Francisco. The ideal candidate will support compliance programs such as SOC 2 Type II and ISO 27001 while managing audits and risk assessments. This onsite role offers a competitive...Suggested
$150k
...Crusoe Energy Systems LLC is looking for a GRC Analyst in San Francisco, CA to support their Governance, Risk, and Compliance program. The role includes managing user access reviews, supporting audits, and leveraging AI tools for process improvements. Ideal candidates...Suggested$193.8k - $228k
...Senior GRC Analyst II job at Carta. San Francisco, CA. The Problems You'll Solve As a Senior GRC Analyst II , you’ll work to assess regulatory requirements and accordingly establish and maintain governance and risk frameworks. You will build and run security compliance...SuggestedFull time- ...Simile in San Francisco is seeking a Governance, Risk, and Compliance (GRC) Analyst to ensure the integrity of our AI systems. The role revolves around developing security policies, managing compliance, and fostering a culture of security awareness across the company....Suggested
$130k - $150k
...and be part of a high-performing team that believes in each other, come build with us at Crusoe. About This Role We’re seeking a GRC Analyst to support the day-to-day execution of our Governance, Risk, and Compliance program. Reporting to the Head of GRC, this role focuses...SuggestedTemporary work- ...Dormont Manufacturing Co in San Francisco, California is looking for an Associate GRC Analyst to support their Governance, Risk, and Compliance program. This position is ideal for early career professionals seeking hands-on experience with security frameworks and compliance...
$135k - $165k
...Icehouseventures is seeking a proactive GRC Analyst to join our team in San Francisco. This role will support compliance and risk management initiatives essential for maintaining high security standards. The ideal candidate will have 3–5 years of experience in GRC and...Contract work$70 - $80 per hour
...Title: GRC Analyst Location: San Francisco, CA (4 days onsite) Duration: 6+ months Key Responsibilities: • Conduct technical vendor risk assessments (security, privacy, architecture, data handling) for new and existing third parties • Review security...Hourly payFull timeLocal area$125k - $200k
...Fei-Fei Li, Adam D’Angelo, and Guillermo Rauch. About the Role GRC at Simile means acting as the bridge between our technical operations... ...mission. Manage Compliance & Audits: Act as a Customer Trust Analyst to address security-related inquiries. Track compliance status...Flexible hours$135k - $165k
...platform and customer relationships. As we continue to scale, we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security compliance and risk management programs. Why Ivo? Every civilization runs on the same...Contract workFlexible hours- ...Spectraforce Technologies is seeking a Database Analyst III in San Francisco, CA. This hands-on role focuses on automating compliance workflows... ...AI-driven automation. Key responsibilities include designing GRC workflows, building dashboards, and supporting data management....
- ...Associate GRC Analyst The Associate GRC Analyst willsupport our Governance, Risk, and Compliance program. This role iswell-suitedfor anearly careerprofessional looking to gainhands-onexperience with security frameworks, risk assessments, audits, and compliance operations...Internship
- ...IXL Learning in San Francisco is looking for an Associate GRC Analyst to join our security team. In this role, you will support cybersecurity governance, compliance, and audit functions by gathering evidence, conducting vendor risk assessments, and maintaining documentation...
$161.6k - $202k
...— and that responsibility demands a security and compliance program that scales with the business. We're building out our dedicated GRC team to improve and mature our program! You'll join the Security team and work across four pillars: security certifications (HITRUST...Full timeWork from homeFlexible hours- ...Ivo is looking for a proactive GRC Analyst to enhance its compliance programs including SOC 2 Type II and ISO 27001. The role demands a detail-oriented individual responsible for managing compliance initiatives and risk assessments while ensuring close collaboration with...
- ...States Digital Space LLC is seeking a Security Risk and Compliance Analyst in San Francisco. You will enhance and operate compliance... ...execution. This role offers a unique opportunity for those with GRC experience to refine technical skills while collaborating with diverse...
$135k - $165k
...Ivo AI, Inc. is looking for a Governance, Risk & Compliance (GRC) Analyst based in San Francisco. This role involves supporting compliance programs, conducting risk assessments, and maintaining security policies. The ideal candidate has 3–5 years of related experience...Flexible hours- ...Ivo Inc. is seeking a GRC Analyst to support compliance and risk management initiatives in their San Francisco office. This is a crucial role designed to maintain Ivo's security compliance across multiple standards including SOC 2 Type II and ISO 27001. The successful...Work at office
- Lambda, a leader in AI cloud infrastructure in San Francisco, is seeking a Cybersecurity Risk Manager. You’ll validate security controls, assist with risk management, and collaborate with engineering teams to enhance cybersecurity practices. Ideal candidates will have ...Flexible hours
$95k - $130k
...LiveRamp is seeking a Security GRC Analyst in San Francisco to support security risk management, compliance, and reporting efforts. You will collaborate closely with various teams to address and mitigate risks while maintaining high compliance standards. The ideal candidate...Remote work$95k - $130k
...Overview Security GRC Analyst job at LiveRamp. San Francisco, CA. LiveRamp is the data collaboration platform of choice for the world's most innovative companies. A groundbreaking leader in consumer privacy, data ethics, and foundational identity, LiveRamp is setting the...Work at officeRemote workWork from homeFlexible hoursNight shift- ...ISO 27001 and 27701, PCI-DSS, SOC, NIST CSF and other regulatory requirements Have a working proficiency with at least one enterprise GRC or TPRM platform: AuditBoard, Vanta, OneTrust, Whistic or equivalent Have familiarity with cloud security controls and compliance in...Work at officeLocal areaWork from homeFlexible hours
- ...NAVA Software solutions is looking for a Security GRC Analyst Details: Security GRC Analyst Location: San Francisco , CA - Hybrid Duration: 6 months CTH Qualifications: Analyst with 2+ years' experience and with good understanding...
$93.8k - $116.3k
Job Description Job Description Company Description Sia is a next-generation, global management consulting group. Founded in 1999, we were born digital. Today our strategy and management capabilities are augmented by data science, enhanced by creativity and driven...Work at officeRemote workWorldwideVisa sponsorshipWork visaFlexible hours3 days per week$100k - $140k
...Affirm is looking for a Compliance Analyst II in San Francisco to enhance its compliance governance program. This role involves reviewing internal compliance processes, investigating consumer complaints, and collaborating with cross-functional teams to ensure adherence...Remote work- A leading global management consultancy is seeking a Consultant specializing in technology and fintech to join their San Francisco office. In this client-facing role, you will lead engagements that deliver impactful solutions across risk, compliance, and operations. The...Work at office
- The Goldman Sachs Group is seeking an Associate for their Global Compliance team in San Francisco. This role involves monitoring compliance, assessing financial products for suitability, and advising on regulations. Ideal candidates will possess a Bachelor's degree and ...
- ...stakeholders 3-5 years of experience in Governance, Risk & Compliance (GRC), Information Security, IT Audit, or related field Hands-on... ...job involves Ivo is seeking a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and...
- ...Roe is seeking a part-time Fraud Analyst based in the San Francisco Bay Area to identify and resolve fraudulent activities. This hybrid role will involve collaborating with team members to develop fraud prevention strategies and conducting detailed fraud analyses. The...Part timeRemote work
$185k - $275k
..., and partnering cross functionally to address customer risk, compliance, and integrity at scale. About the Role As a Fraud & Risk Analyst, you will develop and operate fraud detection, investigation, and risk management systems using automation, machine learning, and human...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!
Related searches


